SafePal data breach: nearly 40,000 users at risk of phishing attacks

On August 16, hardware crypto wallet manufacturer SafePal officially confirmed a data breach incident affecting approximately 39,798 customers. User names, shipping addresses, phone numbers, email addresses, and order details fell into the hands of third parties. This is a serious signal for the entire sector, as such information is a goldmine for scammers specializing in social engineering.
It is important to emphasize: critically sensitive data such as seed phrases, private keys, passwords, banking details, and card numbers were not compromised. The company does not store this information on its servers, which is a security standard for hardware wallets. At this time, there is no evidence that attackers gained access to user funds or their crypto assets.
However, the main threat lies in potential targeted attacks. The leak of personal data opens a wide field for phishing: scammers may call, message via messengers, impersonate SafePal support, offer "refunds," or demand "urgent firmware updates." The project team is already actively monitoring fake resources and working to get them blocked, but users should exercise heightened vigilance.
Cause of the incident and the team's response
The root of the problem is an authorization flaw in a third-party order tracking plugin. This module, connected to customer data, incorrectly handled access requests, allowing an unauthorized person to view other customers' orders. By the time the statement was published, the vulnerability had been fixed and security measures strengthened.
The incident affected orders placed between March 2, 2025, and April 11, 2026. The company has not yet disclosed the exact timeframe of the vulnerability's exploitation, raising questions about the transparency of the investigation. Currently, SafePal is conducting an internal investigation together with an independent security company and plans a full audit of the entire order processing system.
In accordance with regulatory requirements, the firm has reduced the data retention period in this system to 90 days and notified logistics partners, asking them to check their systems for potential impact. Notably, this is already the second such case within a week: on August 13, a similar leak occurred at SafePal's competitor, the Trezor project, where nearly 14,000 customers were affected due to a breach at logistics partner ShipMonk.
My analysis: This wave of incidents is a wake-up call for the entire industry. Even if the wallets themselves are protected at the hardware level, data leaks at the order processing level create a breeding ground for phishing. I recommend that all hardware wallet users ignore any messages about "urgent updates" or "refunds" and always manually verify official website addresses.